CVE-2018-7431
Directory traversal vulnerability in the Splunk Django App in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allows remote…
Does this matter?
Lower severity and a low EPSS score (2.28%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in the Splunk Django App in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allows remote authenticated users to read arbitrary files via unspecified vectors.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.28% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- splunk/splunk
- Source
- cve@mitre.org
References
- https://www.splunk.com/view/SP-CAAAP5TVendor Advisory
- https://www.splunk.com/view/SP-CAAAP5TVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.